Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 273924 (CVE-2009-1384) - <sys-auth/pam_krb5-? user enumeration (CVE-2009-1384)
Summary: <sys-auth/pam_krb5-? user enumeration (CVE-2009-1384)
Alias: CVE-2009-1384
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
Whiteboard: B4 [invalid]
Depends on:
Reported: 2009-06-12 21:24 UTC by Stefan Behte (RETIRED)
Modified: 2010-04-30 17:38 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-06-12 21:24:12 UTC
CVE-2009-1384 (
  pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux
  (RHEL) 5, generates different password prompts depending on whether
  the user account exists, which allows remote attackers to enumerate
  valid usernames.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2009-06-12 21:26:34 UTC
I'm not sure about the versioning, BUT even if I'm wrong, this bug has it's use to remind you to remove older, vulnerable versions <3.12 from tree.
Comment 2 Michael Hammer (RETIRED) gentoo-dev 2009-06-15 07:32:10 UTC
the red hat pam_krb5 and ours (from Russ Allbery) have a different codebase AFAIK. But on the other hand it doesn't hurt to clean up old pam_krb5 releases.

Therefore -> fixed. g, mueli
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2009-06-15 17:00:32 UTC
I had in mind that there was something up with pam_krb5; now I had a look: our package is called "sys-auth/pam_krb5" in portage, but in fact it is pam-krb5 (note the hyphon/underscore); the redhat package is the "real" pam_krb5.